Signadot CLI
This is the source repository for the Signadot command-line interface.
Please see the CLI reference for installation and usage instructions.
To file an issue, please use our community issue tracker.
NOTE: Starting next release, and hence in the main branch, this repository has a dependency
on a private repository, and hence building or running from source will not work.
Previous releases should continue to work.
Install
To install the CLI, run:
curl -sSLf https://raw.githubusercontent.com/signadot/cli/main/scripts/install.sh | sh
By default, the script will install the latest version at /usr/local/bin/signadot. The target version can be selected by setting the SIGNADOT_CLI_VERSION variable, while you can specify the install directory with SIGNADOT_CLI_PATH.
Build
To build the CLI from source, such as to test changes, you'll need Go 1.18+.
The main package is in cmd/signadot:
Release
To release the CLI, you can use the release Github action.
Push a new tag that matches the format v[0-9]+.[0-9]+.[0-9]
and it will push new release artifacts and update brew.
Post-release: publish to the MCP Registry
After the GitHub release artifacts are live, publish the MCP server entry
manually. goreleaser does not yet support the fileSha256 integrity field
required by the MCP registry for mcpb packages.
Prerequisites:
- install
mcp-publisher
- a classic GitHub PAT with only the
read:org scope
(create one here),
owned by an Owner of the signadot org. Since
registry#1383
the registry grants the io.github.signadot/* namespace only to org Owners,
and the interactive mcp-publisher login github device flow cannot read org
roles — logging in with a PAT is what makes org publishing work.
./scripts/gen-mcp-server-json.sh <version>
MCP_GITHUB_TOKEN=<pat-with-read:org> mcp-publisher login github
mcp-publisher publish server.json
See Also
The CLI is built on top of the Go SDK.
The CLI is built using libconnect.